VORANT. Threat Intelligence Sign in Get the full feed

Rhysida claims breach of CRI Electric

high threat government-nationaldefensemanufacturing

Rhysida ransomware group listed San Antonio electrical contractor CRI Electric as a victim, claiming theft of federal employee credentials, vendor SSNs, and bid data.

Ransomware.live tracking indicates the Rhysida ransomware group has listed CRI Electric, a veteran-owned San Antonio electrical services company, as a victim on its leak site, with an estimated attack date of August 22, 2026. The claimed stolen data is notably sensitive for a small business of this size, allegedly including employee federal account artifacts (Login.gov recovery keys, TSP retirement data, ID.me, DoD DS Logon, and PIEE contract payment system access), 151 vendor W-9 forms containing SSNs/EINs, payroll records, privileged HR-lawyer correspondence, OSHA injury reports with photos, public-sector bid pricing for government entities (SAWS, SAISD, NISD), corporate governance documents, QuickBooks financials, and a Power of Attorney.

The exposure of DoD-adjacent credentials (DS Logon, PIEE) and CUI-adjacent bid data is significant given CRI Electric's apparent status as a small/veteran-owned government contractor (SDVOSB), raising downstream risk for federal systems and other public-sector entities if credentials are reused or if identity documents enable further fraud. No specific initial-access vector, malware sample, or technical IOC was disclosed in this listing; the entry is a leak-site claim rather than a technical intrusion report. Organizations with similar profiles — small contractors holding DoD-linked credentials or PII for federal employees — should treat this as a reminder to audit third-party/vendor access to sensitive federal identity systems and enforce credential rotation and MFA on Login.gov, ID.me, and DS Logon accounts tied to contract relationships.

Mentioned in this report

Threat actors rhysida
Malware Rhysida

Source reporting: https://www.ransomware.live/id/Q1JJIEVsZWN0cmljQHJoeXNpZGE=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free